Two-Factor Authentication for Business: A Practical Guide to MFA
Two-factor authentication for business: MFA methods compared, a 6-step rollout, real costs and NIS2. TN Solutions, Melzo (Milan). Call +39 02 9517550.

In this article
- 01What Is Two-Factor Authentication (and How It Differs from MFA)
- 02Why Enable It Now: The Numbers, Insurers and NIS2
- 03MFA Methods Compared: Which One Is Right for Your Business
- 04How to Implement MFA in Your Business in 6 Steps
- 05The Mistakes We See Most Often
- 06What Two-Factor Authentication Costs an SME
- 07Roll Out MFA with a Team That Has Done It for 25 Years
Two-factor authentication for business (2FA/MFA) adds a second identity check on top of the password — an app notification, a one-time code or a physical security key — before granting access to email, business applications and VPNs. It blocks the vast majority of attacks based on stolen credentials, can be rolled out in a matter of days, and on Microsoft 365 it is included at no extra licensing cost.
In this guide we look at how it works, which methods to choose, how to introduce it without disrupting people's day-to-day work, and what it really costs a small or mid-sized business. Everything here comes from what we do week in, week out for our clients: TN Solutions is an ISO 9001 and ISO 27001 certified System Integrator, and MFA is almost always the first measure we recommend in any business cyber security project.
What Is Two-Factor Authentication (and How It Differs from MFA)
Two-factor authentication requires two proofs of identity of a different nature, drawn from three categories:
- Something you know: a password or PIN.
- Something you have: a smartphone running an authenticator app, a hardware token, a smart card.
- Something you are: a fingerprint or facial recognition.
2FA means exactly two factors; MFA (Multi-Factor Authentication) is the broader term — "two or more factors". In everyday business use the two terms are effectively interchangeable. One common misconception is worth clearing up, though: password + security question is not 2FA, because both are "something you know". The second factor must come from a different category.
Why a Password on Its Own Is No Longer Enough
Business passwords end up in the wrong hands in three ways: phishing (a user types it into a look-alike site), data breaches at third-party services where it was reused, and infostealer malware that lifts it straight from the browser. In all three cases the attacker holds a valid credential — and to your systems they are indistinguishable from a legitimate employee. The second factor breaks that pattern: a stolen password, on its own, no longer opens anything.
Why Enable It Now: The Numbers, Insurers and NIS2
Three reasons make two-factor authentication for business a priority rather than a nice-to-have:
- Effectiveness out of all proportion to the cost. Microsoft estimates that MFA blocks over 99% of automated account-compromise attacks. No other security measure comes close to that benefit-to-effort ratio.
- Insurers and customers expect it. Cyber insurance policies now routinely list MFA as a prerequisite for cover — or a reason to deny a claim. More and more large customers ask for it in supplier qualification questionnaires.
- The regulators take it as read. The NIS2 Directive explicitly names multi-factor authentication solutions among the expected risk-management measures. If your organisation falls within its scope — or supplies one that does — MFA is a mandatory starting point. We cover this in detail in our article on what NIS2 changes for SMEs.
Then there is the most concrete reason of all: a large share of the ransomware incidents we deal with begin with a VPN or email account protected by nothing but a password. To understand the full attack chain, see our guide on how to protect your business from ransomware.
MFA Methods Compared: Which One Is Right for Your Business
Not all second factors are created equal. Here are the main options, from weakest to strongest.
One-Time Codes via SMS or Email
A one-time code delivered by SMS is better than nothing, but it is the most vulnerable method: SIM swapping, interception and real-time phishing all get around it. It is acceptable as a fallback for users without a company smartphone — not as the standard.
Authenticator Apps with TOTP Codes
Apps such as Microsoft Authenticator or Google Authenticator generate a six-digit code that changes every 30 seconds, and they work offline. A good balance of security and simplicity, and free of charge. It remains exposed to sophisticated phishing, however: a cloned site can prompt the user for the code as well and replay it within its validity window.
Push Notifications with Number Matching
The app shows an "Is this you signing in?" notification and asks the user to enter the number displayed on the login screen. Number matching matters: it neutralises MFA fatigue attacks, where a criminal bombards the user with prompts hoping for one absent-minded "Approve". This is the method we recommend as the default for most SMEs on Microsoft 365.
FIDO2, Passkeys and Hardware Tokens
Physical security keys (YubiKey and similar) and passkeys built on the FIDO2 standard are the only method that is phishing-resistant by design: the cryptographic check is bound to the genuine domain, so a cloned site gets nothing. They are the right choice for IT administrators, senior management, the finance team and anyone who authorises payments.
Rule of thumb: push with number matching for everyone, FIDO2/passkeys for privileged accounts, SMS only as a documented exception.
How to Implement MFA in Your Business in 6 Steps
The classic mistake is "switch everything on Monday morning". A well-run project takes one to two weeks and follows this path:
- Map your critical access points. Email and Microsoft 365, VPN and remote access, ERP and line-of-business systems, online banking, cloud consoles and IT admin panels. The VPN deserves particular attention: remote access without MFA is attackers' favourite way in.
- Choose your methods and platform. If you run Microsoft 365, Entra ID covers MFA without additional licences; Business Premium plans add Conditional Access on top. You will find the full picture in our guide to Microsoft 365 for business.
- Define policies by group. IT administrators first (immediately, no exceptions), then management and finance, then everyone else in waves. With Conditional Access you can reduce prompts on managed company devices and on-premises, and tighten them for sign-ins from outside.
- Communicate and train. A clear message to staff — why we are doing this, what changes, who to call if something goes wrong — halves the support tickets. Five minutes of training on number matching, and on never approving a prompt you did not trigger, is worth more than any technology.
- Prepare the recovery process. Decide up front what happens when an employee loses their phone: backup codes kept safely, a second registered method, an identity-verification procedure at the help desk. This is where DIY projects run aground.
- Close the back doors. Disable legacy protocols (IMAP/POP/SMTP basic authentication) that bypass MFA, and monitor your sign-in logs. MFA switched on with legacy authentication still open is a reinforced front door with the window left wide open.
The Mistakes We See Most Often
- MFA on webmail only. VPN, ERP and admin panels stay exposed — so that is where the attacker goes in.
- "Temporary" exceptions for senior management. Those are precisely the most attractive accounts; the exceptions become permanent and everyone forgets they exist.
- No recovery procedure. The first lost phone triggers panic and the temptation to switch the whole thing off.
- Push approval without number matching. It leaves the door open to MFA fatigue.
- Treating it as the finish line. MFA drastically cuts the risk of account takeover, but it does not replace endpoint protection or backups: it is one layer in a defence-in-depth strategy, alongside tools such as EDR.
What Two-Factor Authentication Costs an SME
For many SMEs the licence cost is close to zero: MFA is included in Microsoft 365 and Google Workspace, and authenticator apps are free. The real cost items are:
- Project and configuration: access mapping, policies, Conditional Access, closing down legacy protocols. For an SME of 10–50 users this typically means a few days of work.
- Hardware tokens (only where needed): roughly €25–60 per FIDO2 key, usually for a minority of privileged users.
- Ongoing management: onboarding new starters, resets, log monitoring. Often this fits within an existing support agreement.
Set against the average cost of a compromised email account — payment fraud, operational downtime, data-protection notifications — the return on investment is among the fastest anywhere in IT security.
Roll Out MFA with a Team That Has Done It for 25 Years
TN Solutions has been designing and managing two-factor authentication for businesses across more than 25 years as a System Integrator: access mapping, Conditional Access policies on Microsoft 365, FIDO2 tokens for privileged accounts and ongoing support, backed by ISO 9001 and ISO 27001 certified processes (Google rating: 4.7/5 from 37 reviews).
If you want to work out where to start, the first conversation costs nothing: get in touch online or call 02 9517550. We are based in Melzo, just outside Milan, and support clients across Italy and Europe both remotely and on-site.
Frequently asked questions
Is MFA a legal requirement?
There is no blanket legal obligation, but the NIS2 Directive names it explicitly among the measures expected of in-scope organisations, the GDPR requires measures "appropriate to the risk", and cyber insurers demand it. In practice, for any structured business it is now the expected standard.
Do employees have to use their personal smartphones?
Not necessarily. The options are: an authenticator app on a personal phone (it requires no invasive permissions and gives the company no access to the device), a company phone, or a hardware token for anyone who prefers not to use a smartphone at all. The choice should also be agreed with employee representatives where applicable.
What happens if a user loses their phone?
If the procedure has been prepared, nothing dramatic: the help desk verifies the person's identity, revokes the methods registered on the old device and enrols a new one — or the user falls back on their backup codes. That is why recovery must be defined before the rollout, not after the first incident.
Does MFA slow people down?
Not with the right policies. Conditional Access asks for the second factor only when it is genuinely needed: on managed company devices and on the office network the prompts can be reduced or removed, while they always fire for anomalous sign-ins or access from external networks.
Does MFA stop phishing 100%?
No. "Adversary-in-the-middle" phishing kits can steal the session even after MFA has been completed with codes or push approvals. That is why we recommend FIDO2/passkeys for critical accounts, plus complementary controls on endpoints and email. MFA nonetheless remains the single most effective measure against account takeover.
Technology partners
Want to discuss it with our team?
We analyse your infrastructure for free and propose the most suitable solution.







